Lucene search

K
cve[email protected]CVE-2014-4060
HistoryAug 12, 2014 - 9:55 p.m.

CVE-2014-4060

2014-08-1221:55:07
CWE-416
web.nvd.nist.gov
29
cve-2014-4060
use-after-free vulnerability
mcplayer.dll
microsoft
windows media center
remote code execution

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.421 Medium

EPSS

Percentile

97.3%

Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka “CSyncBasePlayer Use After Free Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_media_centerMatch-
AND
microsoftwindows_8Match-professional
OR
microsoftwindows_8.1Match-professional
Node
microsoftwindows_media_center_tv_packMatch-
AND
microsoftwindows_7Match-sp1enterprise
OR
microsoftwindows_7Match-sp1enterprise_kn
OR
microsoftwindows_7Match-sp1enterprise_n
OR
microsoftwindows_7Match-sp1home_premium
OR
microsoftwindows_7Match-sp1home_premium_kn
OR
microsoftwindows_7Match-sp1home_premium_n
OR
microsoftwindows_7Match-sp1professional
OR
microsoftwindows_7Match-sp1professional_kn
OR
microsoftwindows_7Match-sp1professional_n
OR
microsoftwindows_7Match-sp1ultimate
OR
microsoftwindows_7Match-sp1ultimate_kn
OR
microsoftwindows_7Match-sp1ultimate_n
OR
microsoftwindows_vista

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.421 Medium

EPSS

Percentile

97.3%